Junglewise Threat Intelligence

CVE-2026-55042: Microsoft Office information disclosure via uninitialized resource

CVE-2026-55042 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Office LTSC 2024, Microsoft Office LTSC for Mac 2024, Microsoft Office 365 for Mac, Microsoft Office LTSC for Mac 2021, Microsoft Office LTSC 2021, Microsoft Office 2016, Microsoft 365 Apps for Enterprise, Microsoft Office 2019. Vendors: Microsoft.

Executive brief

A security vulnerability in Microsoft Office could allow an attacker to access sensitive information on a user's computer. To exploit this, an attacker would typically need to convince a user to open a specially crafted file. This could lead to the unauthorized disclosure of private data stored in the system's memory.

Technical details

A vulnerability classified as CWE-908 (Use of Uninitialized Resource) exists in multiple versions of Microsoft Office, including Office 2016, 2019, LTSC, and Microsoft 365 Apps. The flaw allows a local attacker to disclose sensitive information by leveraging uninitialized memory resources. Exploitation requires user interaction, typically involving the victim opening a malicious file. Successful exploitation results in a high impact on confidentiality but does not affect integrity or availability. Microsoft has released security updates to address this issue across affected platforms.

Affected products

  • Microsoft Microsoft 365 Apps for Enterprise 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office 2016 16.0.0 to 16.0.5561.1000
  • Microsoft Microsoft Office 2019 19.0.0 and later versions prior to security updates
  • Microsoft Microsoft Office 365 for Mac 1.0.0 to 16.111.26071215
  • Microsoft Microsoft Office LTSC 2021 16.0.1 and later versions prior to security updates
  • Microsoft Microsoft Office LTSC 2024 16.0.0 and later versions prior to security updates
  • Microsoft Microsoft Office LTSC for Mac 2021 16.0.1 to 16.111.26071215
  • Microsoft Microsoft Office LTSC for Mac 2024 16.0.0 to 16.111.26071215

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats